Unpatched Flaws Disclosed in Filesystem Bundled Into Millions of Embedded Devices

2026-07-04T01:24:08Zba321122a9e92a97906cff407ebb033bfa952a36a5269f28ae31876e74ec62a4
active-exploitationadobe-patchesandroidargocdavalonbad-epollchocopoccitrix-bleed-2credential-theftembedded devicesfatfskuberneteslinux-kernelmacosmalwarenetnutnorth-korea-linkednpm-supply-chainpamstealerpegasusprivilege-escalationransomwareresidential-proxysharepointspyware

What happened

A wide-ranging set of security incidents and vulnerabilities affecting embedded devices, cloud and enterprise software, and multiple malware campaigns. RunZero disclosed seven unpatched flaws in FatFs affecting millions of embedded devices. A critical Linux kernel local-privilege-escalation (Bad Epoll, CVE-2026-46242) affects desktops, servers and Android. New modular malware (Avalon) bundles ransomware (CrownX) capabilities; several info-stealers and RATs (PamStealer, ChocoPoC, PureLogs, PureLogs/VEIL#DROP, Ousaban, Umbrij) and supply-chain attacks (malicious npm packages mimicking Rollup) or

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
ba321122a9e92a97906cff407ebb033bfa952a36a5269f28ae31876e74ec62a4
Enrichment time
2026-07-04T01:24:08Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Unpatched Flaws Disclosed in Filesystem Bundled Into Millions of Embedded Devices · Baitaphish